← KOULUTUKSET
SC-500

Implement end‑to‑end security controls for cloud and AI workloads

Palveluiden siirtyessä yhä enemmän pilveen tulee myös niitä tilaavien, suunnittelevien ja toteuttavien tahojen ymmärtää millä tavalla tietoturvaa toteutetaan pilviratkaisuissa.
KESTO 4 päivää
Moduuleja 12

Tämän kurssin edeltäjä AZ-500 keskittyi esittelemään Azuressa olevia tietoturva-palveluita. Nyt palvelut alkavat olla siinä vaiheessa, että on syytä aloittaa niiden turvaaminen. Tässä koulutuksessa käydään laajasti lävitse Azuren palveluita ja niiden turvaamiseen liittyviä toimenpiteitä. Vaikka olisit pitkään ylläpitänyt Azure palveluita, niin tämä on hyvä katsaus niihin tietoturvaan liittyviin määrityksiin, jotka on syytä saattaa ajan tassalle.

 

// KURSSIN OHJELMA

Sisältö

MODULE 1

Secure Access to resources using Microsoft Entra ID

  • Manage and Implement Authentication Methods in Microsoft Entra ID
  • Implement and configure Privileged Identity Management (PIM)
  • Authenticate your API plugin for declarative agents with secured APIs
  • Lab: Configure Privileged Identity Management
  • Lab: Configure Privileged Identity Management
MODULE 2

Secure secrets and keys using Azure Key Vault

  • Configure and secure Azure Key Vault
  • Manage Keys and Secrets in Azure Key Vault
  • Manage Certificates and Monitor Azure Key Vault
  • Protect Azure Key Vault with Microsoft Defender for Cloud
  • Lab: Deploy and Secure Azure Key Vault
MODULE 3

Implement governance to enforce security and regulatory compliance

  • Enforce Governance with Azure Policy and Resource Locks
  • Configure Security Controls and Remediate Recommendations in Defender for Cloud
  • Evaluate Regulatory Compliance in Defender for Cloud
  • Manage and Right-Size RBAC Role Assignments for Least Privilege
  • Protect Backup Data with Azure Backup Security Features
  • Implement Security Controls in Infrastructure as Code
  • Lab: Configure Azure Policy and Role-Based Access Control
MODULE 4

Implement security for storage accounts

  • Describe Azure storage services
  • Implement Security and Manage Access for Azure Storage
  • Configure Network Security for Azure Storage
  • Implement Microsoft Defender for Storage
  • Lab: Secure Azure Storage
MODULE 5

Implement security for Azure SQL databases

  • Configure Platform-Level Security for Azure SQL
  • Configure Auditing for Azure SQL Database and SQL Managed Instance
  • Implement Microsoft Defender for Databases
  • Lab: Secure Azure SQL Database

 

MODULE 6

Implement security for Azure networking

  • Segment and Isolate Azure Workloads Using Network Security Controls
  • Centralize and Enforce Traffic Inspection Using Azure Firewall
  • Secure Remote and Hybrid Connectivity Using VPN Gateways and Microsoft Entra Private Access
  • Eliminate Public Network Exposure of Azure PaaS Services
  • Lab: Configure Network Security Controls
MODULE 7

Implement security for AI

  • Secure Access for Microsoft Entra Agent Identity
  • Analyze AI Identity Risks Using Microsoft Defender XDR
  • Enable Real-Time Protection for Copilot Studio Agents
  • Configure AI Gateway Security in Microsoft Foundry
  • Configure and manage guardrails in Microsoft Foundry
  • Protect AI workloads with Microsoft Defender for Cloud
  • Enable Defender for AI Services Workload Protection in Microsoft Defender for Cloud
  • Manage Agents Using Microsoft Agent 365
  • Identify AI Data Risks Using Microsoft Purview Data Security Posture Management
  • Lab: Configure AI Gateway and Foundry Security Controls
  • Lab: Monitor AI Security with Defender for Cloud
MODULE 8

Implement security for servers and virtual machines

  • Implement Disk Encryption for Azure Virtual Machines
  • Configure Trusted Launch Security Features for Azure Virtual Machines’
  • Plan and Implement Azure Bastion
  • Manage Security for Arc-Enabled Hybrid Servers
  • Implement Microsoft Defender for Servers
  • Enable and Enforce Just-in-Time VM Access
  • Enforce VM Security Configuration with Azure Machine Configuration
MODULE 9

Manage security posture by using Defender for Cloud

  • Connect Hybrid and multicloud Environments to Microsoft Defender for Cloud
  • Identify Security Risks by Using Cloud Security Posture Management
  • Discover Unprotected Assets and Vulnerabilities by Using Microsoft Defender External Attack Surface Management
  • Evaluate Regulatory Compliance in Defender for Cloud
  • Enable and Configure Workload Protection Plans in Microsoft Defender for Cloud
  • Configure Microsoft Defender Vulnerability Management Settings for Azure VMs
  • Labs
MODULE 10

Implement activity and event collections in Microsoft Sentinel

  • Create and manage Microsoft Sentinel workspaces
  • Manage content in Microsoft Sentinel
  • Connect Microsoft services to Microsoft Sentinel
  • Connect syslog data sources to Microsoft Sentinel
  • Connect Common Event Format logs to Microsoft Sentinel
  • Connect Windows hosts to Microsoft Sentinel
  • Implement Automation Rules and Playbooks in Microsoft Sentinel
  • Manage Data Storage and Query Audit Logs in Microsoft Sentinel
  • Lab: Configure Microsoft Sentinel Data Collection and Automation
MODULE 11

Implement Microsoft Security Copilot

  • Describe Microsoft Security Copilot
  • Configure workspaces for Microsoft Security Copilot
  • Manage Plugins and Agents in Microsoft Security Copilot
  • Lab: Configure and Use Microsoft Security Copilot